Serravee

Security that holds up to your security team.

Serravee connects to the tools your brand runs on with only the access each job needs. Your data is encrypted, your accounts stay yours, and our terms are public.

Your accounts, your call.

Serravee works through each platform’s own permissions, with the narrowest access the job allows. You choose what to connect and can revoke any connection at any time.

Every action is logged with what was done, why, and who approved it, so your team can check the record.

Where your data goes.

Kept separate

Each brand’s data stays separate from every other account.

Service providers

We use service providers to run Serravee. Our sub-processor list names each one and its purpose, and our Privacy Policy explains how we use data.

Where processing happens

Serravee processes personal data in the United States. The DPA describes the agreements available for international transfers.

Deletion

On termination or your written instruction, we delete personal data within 30 days, except what the law requires us to retain. Encrypted backups age out within 90 days. We confirm deletion in writing if you ask.

Terms you can read before you sign.

Our commitments are written down and public.

  • 72h

    Breach notice

    Within 72 hours of confirming a breach that affects your data.

  • 30

    Days to delete

    Personal data deleted after termination or your written instruction.

  • 30

    Days’ notice

    Before we add or replace a sub-processor.

  • Data Processing Agreement

    Live

    Covers data handling, security measures, audit rights, deletion and breach notice. Read the DPA.

  • Sub-processor list

    Live

    We give at least 30 days’ notice before we add or replace a sub-processor. Read the list.

What the DPA commits to

These are contractual commitments, not an independent audit report.

Security measures

Encryption in transit and at rest, least-privilege access reviewed regularly, credentials you can revoke, logging of every action, and separation of customer data between accounts. Read the full security terms.

Breach notification

Notice without undue delay, and within 72 hours of confirming a personal data breach affecting your data. We share what we know and keep you updated.

Your audit rights

You may audit once in any 12-month period on 30 days’ written notice, subject to the terms in the DPA. Further audits are allowed when a regulator directs one or after a confirmed breach of your data.

Questions from your security team?

Send security reviews and vulnerability reports to security@serravee.com. Our DPA, Privacy Policy and sub-processor list are public.